First published: Tue Jun 23 2015(Updated: )
`Zend/Diactoros/Uri::filterPath` in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/zendframework/zend-diactoros | >=1.0.0<1.0.4 | |
Zend Diactoros | <=1.0.3 | |
composer/zendframework/zend-diactoros | >=1.0.0<1.0.4 | 1.0.4 |
<=1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.